2550 vulnerabilidades · Web · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2013-7240
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
41.5%
2013 2 PoCs

Directory traversal vulnerability in download-file.php in the Advanced Dewplayer plugin 1.2 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the dew_file parameter.

CVE-2023-39650
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
35.0%
2023 0 PoCs

Theme Volty CMS Blog up to version v4.0.1 was discovered to contain a SQL injection vulnerability via the id parameter at /tvcmsblog/single.

CVE-2023-1893
Login Configurator Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
4.9%
2023 2 PoCs

The Login Configurator WordPress plugin through 2.1 does not properly escape a URL parameter before outputting it to the page, leading to a reflected cross-site scripting vulnerability targeting site administrators.

CVE-2019-13372
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
92.9%
2019 3 PoCs

/web/Lib/Action/IndexAction.class.php in D-Link Central WiFi Manager CWM(100) before v1.03R0100_BETA6 allows remote attackers to execute arbitrary PHP code via a cookie because a cookie's username field allows eval injection, and an empty password bypasses authentication.

CVE-2020-11529
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
70.3%
2020 0 PoCs

Common/Grav.php in Grav before 1.7 has an Open Redirect. This is partially fixed in 1.6.23 and still present in 1.6.x.

CVE-2020-24148
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
92.8%
2020 1 PoC

Server-side request forgery (SSRF) in the Import XML and RSS Feeds (import-xml-feed) plugin 2.0.1 for WordPress via the data parameter in a moove_read_xml action.

CVE-2019-17574
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
86.9%
2019 1 PoC

An issue was discovered in the Popup Maker plugin before 1.8.13 for WordPress. An unauthenticated attacker can partially control the arguments of the do_action function to invoke certain popmake_ or pum_ methods, as demonstrated by controlling content and delivery of popmake-system-info.txt (aka the "support debug text file").

CVE-2020-35234
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
81.5%
2020 0 PoCs

The easy-wp-smtp plugin before 1.4.4 for WordPress allows Administrator account takeover, as exploited in the wild in December 2020. If an attacker can list the wp-content/plugins/easy-wp-smtp/ directory, then they can discover a log file (such as #############_debug_log.txt) that contains all password-reset links. The attacker can request a reset of the Administrator password and then use a link found there.

CVE-2019-17564
Apache Dubbo Web ⚡ nuclei
N/A
UNKNOWN
EPSS
94.0%
2019 6 PoCs

Unsafe deserialization occurs within a Dubbo application which has HTTP remoting enabled. An attacker may submit a POST request with a Java object in it to completely compromise a Provider instance of Apache Dubbo, if this instance enables HTTP. This issue affected Apache Dubbo 2.7.0 to 2.7.4, 2.6.0 to 2.6.7, and all 2.5.x versions.

CVE-2020-13942
Apache Unomi Web ⚡ nuclei
N/A
UNKNOWN
EPSS
94.3%
2020 CWE-20 7 PoCs

It is possible to inject malicious OGNL or MVEL scripts into the /context.json public endpoint. This was partially fixed in 1.5.1 but a new attack vector was found. In Apache Unomi version 1.5.2 scripts are now completely filtered from the input. It is highly recommended to upgrade to the latest available version of the 1.5.x release to fix this problem.

CVE-2020-9043
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
29.6%
2020 1 PoC

The wpCentral plugin before 1.5.1 for WordPress allows disclosure of the connection key.

CVE-2019-6703
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
54.7%
2019 1 PoC

Incorrect access control in migla_ajax_functions.php in the Calmar Webmedia Total Donations plugin through 2.0.5 for WordPress allows unauthenticated attackers to update arbitrary WordPress option values, leading to site takeover. These attackers can send requests to wp-admin/admin-ajax.php to call the miglaA_update_me action to change arbitrary options on affected sites. This can be used to enable new user registration and set the default role for new users to Administrator.

CVE-2020-18268
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
9.2%
2020 0 PoCs

Open Redirect in Z-BlogPHP v1.5.2 and earlier allows remote attackers to obtain sensitive information via the "redirect" parameter in the component "zb_system/cmd.php."

CVE-2020-17362
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
3.9%
2020 0 PoCs

search.php in the Nova Lite theme before 1.3.9 for WordPress allows Reflected XSS.

CVE-2023-3077
MStore API Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
66.8%
2023 1 PoC

The MStore API WordPress plugin before 3.9.8 does not sanitise and escape a parameter before using it in a SQL statement, leading to a Blind SQL injection exploitable by unauthenticated users. This is only exploitable if the site owner elected to pay to get access to the plugins' pro features, and uses the woocommerce-appointments plugin.

CVE-2019-6802
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
1.3%
2019 0 PoCs

CRLF Injection in pypiserver 1.2.5 and below allows attackers to set arbitrary HTTP headers and possibly conduct XSS attacks via a %0d%0a in a URI.

CVE-2020-13158
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
91.2%
2020 1 PoC

Artica Proxy before 4.30.000000 Community Edition allows Directory Traversal via the fw.progrss.details.php popup parameter.

CVE-2020-13483
Software Genérico Web Networking ⚡ nuclei
N/A
UNKNOWN
EPSS
26.0%
2020 0 PoCs

The Web Application Firewall in Bitrix24 through 20.0.0 allows XSS via the items[ITEMS][ID] parameter to the components/bitrix/mobileapp.list/ajax.php/ URI.

CVE-2019-14206
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
20.8%
2019 2 PoCs

An Arbitrary File Deletion vulnerability in the Nevma Adaptive Images plugin before 0.6.67 for WordPress allows remote attackers to delete arbitrary files via the $REQUEST['adaptive-images-settings'] parameter in adaptive-images-script.php.

CVE-2020-13379
Software Genérico DevOps Web ⚡ nuclei
N/A
UNKNOWN
EPSS
93.1%
2020 4 PoCs

The avatar feature in Grafana 3.0.1 through 7.0.1 has an SSRF Incorrect Access Control issue. This vulnerability allows any unauthenticated user/client to make Grafana send HTTP requests to any URL and return its result to the user/client. This can be used to gain information about the network that Grafana is running on. Furthermore, passing invalid URL objects could be used for DOS'ing Grafana via SegFault.